Warning

 

Close
Confirm Action

Are you sure you wish to do this?

Cancel Confirm
AR15.COM
1/30/2015 2:14:52 PM EDT
Our computer keeps popping up a message that says "oops, google chrome has crashed.  restart?"  or something to the effect.  I didn't think we even had Google Chrome installed so searched the start menu as well as my programs and there's nothing.  Any idea whats going on?
1/30/2015 2:36:26 PM EDT
[#1]
Check the system tray down by the clock to see if it's running:
1/30/2015 2:39:15 PM EDT
[#2]
Also check programs in your Control Panel.
1/30/2015 3:36:49 PM EDT
[#3]
I didn't see it in either place but I'll look again when I get home later
1/31/2015 7:10:50 PM EDT
[#4]
I've  looked everywhere and Google Chrome def isn't installed.  I installed Chrome and then uninstalled it to see if that would help and nothing.  Norton 360 did pop up a message "High Data Usage by Google Chrome"  I clicked on details and it said Chrome was using 43% of the cpu.  I clicked on locate the file and when it showed me where it was I tried to delete it.  It wont let me delete it because it says its in use by Chrome??  How can it be in use when it's not even installed?
2/1/2015 10:36:45 PM EDT
[#5]
Is Vosteran or WSE Vosteran listed as an installed program?

Do you have the Ask toolbar or the Ask shopping app?

Do you have "Spyware Clear" installed?

Do you have McAffe installed on top of Norton?

2/2/2015 3:29:11 PM EDT
[#6]

Quote History
Quoted:


I've  looked everywhere and Google Chrome def isn't installed.  I installed Chrome and then uninstalled it to see if that would help and nothing.  Norton 360 did pop up a message "High Data Usage by Google Chrome"  I clicked on details and it said Chrome was using 43% of the cpu.  I clicked on locate the file and when it showed me where it was I tried to delete it.  It wont let me delete it because it says its in use by Chrome??  How can it be in use when it's not even installed?
View Quote
You are not dealing with Chrome.

 



You are dealing with an infection that calls itself Chrome. Anybody, can name any program, anything they want.




Boot into safe mode and run a full scan with Norton (to start.)




Get "Combofix" from the web site "Bleeping computer" and run that as well.
2/2/2015 7:47:28 PM EDT
[#7]
OP, did you download Chrome from www.google.com/chrome
2/2/2015 10:09:17 PM EDT
[#8]
Quote History
Quoted:
Is Vosteran or WSE Vosteran listed as an installed program?

Do you have the Ask toolbar or the Ask shopping app?

Do you have "Spyware Clear" installed?

Do you have McAffe installed on top of Norton?

View Quote


Didn't see anything like Volsteran, Ask or Spyware Cleaner but for some reason McAffe was installed along with Norton.  I removed McAffe, rebooted in safe mode and now running a full system scan.

Thanks guys, we'll see what happens
2/2/2015 10:10:17 PM EDT
[#9]
Quote History
Quoted:
OP, did you download Chrome from www.google.com/chrome
View Quote


Didn't download chrome period that I'm aware of, thinking one of the kids might have had something to do with it
2/3/2015 8:00:19 AM EDT
[#10]
Have you looked at task manager yet?
2/3/2015 8:37:16 AM EDT
[#11]
Nothing showed in task manager either.  I booted in safe mode, then ran a scan and it found three Trojan.Gen.2  It seems to be running much faster now, so hopefully we're good to go.  

I was wondering why Norton found these files while running in safe mode but not when running in regular mode, even though it was the same scan?
2/3/2015 9:04:08 AM EDT
[#12]

Quote History
Quoted:
Didn't download chrome period that I'm aware of, thinking one of the kids might have had something to do with it
View Quote View All Quotes
View All Quotes
Quote History
Quoted:



Quoted:

OP, did you download Chrome from www.google.com/chrome




Didn't download chrome period that I'm aware of, thinking one of the kids might have had something to do with it
Ok. Your next strep is to make a non-admin account, lock it down, and change the password on your account.

 



Your kids will continue to fuck up your computer until they are about 25 and have to pay for the fixing themselves if you don't do this.
2/3/2015 11:58:42 AM EDT
[#13]
Quote History
Quoted:
Nothing showed in task manager either.  I booted in safe mode, then ran a scan and it found three Trojan.Gen.2  It seems to be running much faster now, so hopefully we're good to go.  

I was wondering why Norton found these files while running in safe mode but not when running in regular mode, even though it was the same scan?
View Quote


Some types of malware can mask their processes in normal mode, and you're able to catch them in safe mode because the service they use to mask their processes was not loaded.
2/3/2015 3:03:15 PM EDT
[#14]
Well I stopped home at lunch to mess with the computer and it's still doing the same thing.  I opened task manager and it showed no applications running.  I clicked on the processes tab and noticed several Ktckfzvjp.exe running so I tried ending the process of each one but they kept coming right back.  Then I right clicked and clicked Show File Location and tried to delete the file from there but of course it wouldn't let me because it was running.  Here's some pictures I took quick..


2/3/2015 3:08:08 PM EDT
[#15]
Google has zero hits for the the file executable file name.


Therefore, it is random.




And, subsequently, it's an infection.



Stop thinking about this as a Chrome problem and start thinking of it as a "computer is infected" problem.
2/3/2015 3:49:10 PM EDT
[#16]
I understand it's not actually Google, what I don't understand is how to get rid of it.  I thought when Norton found those three during the full scan it was solved
2/3/2015 3:51:28 PM EDT
[#17]
Rkill.
Malwarebytes.
2/5/2015 1:13:04 PM EDT
[#18]
My advice is to wipe the drive and do a fresh install from a known good source.  Then follow the advice above regarding setting up restricted user accounts.
2/5/2015 4:10:58 PM EDT
[#19]
Isn't Kaspersky the "go to" virus program for occasions where others aren't working?  I thought I recall reading somewhere that Norton and McAffe use Kaspersky as their source?